Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

131–140 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#131
post #59

Earlier quoted context omitted.

I get an email claiming that I have unread Linkedin messages. The email uses their Logos. But if I were to click any of the links in the email, it would send me to a php or html file that contains a Javascript redirect script. That script, if executed, then goes to the phishers actual page. Sometimes, there is an additional DNS redirect at the JS redirected page. For some reason, the JS redirect tries to hide the red…

The solution should be to just stop using human generated passwords and instead have each site generate their own and for browsers and apps use password managers built into the OS and offer to fill them in based on the domain. This is increasingly happening. We need the large sites to move to this to eliminate phishing entirely. So https://f00l.com isn’t same as https://fool.com

All you've done there is move the attack target from the website to the users device.

The obvious solution is to remove all users from the internet.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#132

I remember once, when I had an unpatched computer overrun by hostile viruses that rendered it unusable, wondering if one of the botnet-type viruses that want to take over your computer and use it without being undetected would someday get smart enough to recognize other viruses and automatically remove their competition so that they could continue to silently infect you. Like a biological virus, one that kills the ho…

This has been happening for years, especially in the "botnet community". Either someone takes down someone else's botnet through the same bug and patches it or figures out a bug in the botnet and caps it for themselves (for example, getting ops in the CNC channel). I think Microsoft has even done in cooperation this a few times; it's dubious legal territory.

You can see some historical examples, both recent (Mirai had some viruses that went around closing the bug), as well as further in the past (there's one that escapes me, it must have been around 2010?)

I wish I could cite more, I'm going to spend some time researching this and make a list for myself, it's surprisingly interesting!

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#133
post #116

Earlier quoted context omitted.

I've worked as a security analyst at a company and sometimes I would report phishing pages to the webhost. After a while, I realized that half of my emails were being silently quarantined by the company's outbound spam filters due to the included URLs. I was able to manually release them, but I wonder how many emails will then be flagged on the receiving end.

Typically when sending an email with content like that for a notification you'll "defang" the URL by rendering it like "hXXp:// foo (dot) bar (dot) com" or something along those lines to ensure that it isn't automatically flagged and filtered, though it's also common on the receiving end to apply no spam filters to their abuse@ email as well. You'll usually have better luck sending this information to the abuse email…

> you'll "defang" the URL

Wow, that's a phrase I haven't heard in ages.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#134
post #26
post #14

Earlier quoted context omitted.

> An "automatic" update that would potentially cause the router to reboot and bring down the network would go over very poorly with customers, even if it happens at 3 AM. Maybe the the trigger for the automatic reboot could be more complicated than just a time-based trigger. Something like Reboot when localtime > 2AM & localtime Basically reboot unless the router detects the network is being used actively.

What about links that need to be available for failover or during emergencies? What about organizations that operate at those hours? I used to work at a 24 hour retail chain, and some stores in mining towns had their busiest hours around 4AM as busloads of miners came in to shop before the day started. We could _never_ upgrade those stores in the early morning hours.

So you're saying the defaults should be setup for the unusual use cases like you describe, even if that means we get botnets of millions of routers?

You're not going to define one set of secure-by-default rules that's going to work for everyone. Rather, you want to try to define a set of secure-by-default rules that work for most people. Then but the burden of reconfiguration and maintenance on those with unusual needs, rather than the majority.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#135

Earlier quoted context omitted.

Security issues are tricky. Often making people aware of an issue is indistinguishable from having caused the issue.

Why would you hack someone and then tell them you did it (without asking for ransom or something)? Of course the person telling you has good intentions.

Not sure if you're being sarcastic, but there's a whole class of attacks that begin under the guise of "helping" the user.

A hilarious and interesting example: https://www.gimletmedia.com/reply-all/long-distance

Additionally: see all the drama and issues that consistently occur surrounding bug bounty payments, secure disclosure of vulnerabilities, etc.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#136

I remember once, when I had an unpatched computer overrun by hostile viruses that rendered it unusable, wondering if one of the botnet-type viruses that want to take over your computer and use it without being undetected would someday get smart enough to recognize other viruses and automatically remove their competition so that they could continue to silently infect you. Like a biological virus, one that kills the ho…

And of course they did, frustratingly that behavior is industry standard even outside of malware.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#137
post #24
post #8

Earlier quoted context omitted.

I don't think automatic updates would be as disruptive as you think. And having the ability to disable them and apply updates manually, combined with some forewarning like you are talking about (an email that says your router will restart tomorrow at 3am unless you do it sooner), would go a really long way.

A lot of Mikrotik's are installed at WISP's and other ISP's... making unplanned reboots very disruptive. Those of us using them on our corporate networks might be inconvenienced by a temporary outage, but that's unlikely at 3am... however, scheduling and doing these manually is still the best way for enterprise gear.

I doubt that most ISPs who can't be bothered to apply security updates are going to notice a 5 minute reboot.

Split the difference - email the user that an update will apply on $date unless they do it first, or if they delay it (and don't let them delay it indefinitely).

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#139
post #119

Earlier quoted context omitted.

Why so negative?

This is not at all negative. Imagine parent telling some underground rebel group that their revolution would be more successful if they organized it with Jira. Meanwhile, this concern is so far away from the rebels, who are doing just fine with pen and paper, and are more concerned with basic needs like surviving undetected. People are of course excited by this initiative, and wish to contribute how they know. Except…

Not true, you are wrong. Better organization leads to a focus that can solve problems at a greater scale and with easier access to solutions. Your metaphor sucks as well.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#140
post #119

Earlier quoted context omitted.

Why so negative?

This is not at all negative. Imagine parent telling some underground rebel group that their revolution would be more successful if they organized it with Jira. Meanwhile, this concern is so far away from the rebels, who are doing just fine with pen and paper, and are more concerned with basic needs like surviving undetected. People are of course excited by this initiative, and wish to contribute how they know. Except…

I think you have a point, but unfortunately I didn't get it from your first comment as well. It read as a pretty negative comment.

It sounds like the point that you are making is reasonable, though, and unfortunately one that I see play out with a lot of FOSS projects as well. I remember a talk one time where a project lead essentially made the point that every new talk is met with a lot of "I'll setup CI for you" and "I'll setup JIRA for you", but that none of the people who say those things end up contributing code or issues.

For some reason there is a natural desire among some to organize the organizing before the thing to be organized really exists.

Post reply on HN